Author Topic: Unremovable trojan found by avast! Need help please.  (Read 5656 times)

0 Members and 1 Guest are viewing this topic.

Needhelp200

  • Guest
Unremovable trojan found by avast! Need help please.
« on: September 22, 2012, 04:26:34 AM »
Hi, I'm not the best at computers so please bear with me. So I found a trojan earlier today after running a full scan and still can't find a way to remove it or quarintine it. I would appreciate it if someone could find a solution for me.

Some basic info:
File name: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
Severity: High
Status: Threat: Win32:FakeAV-ANO [Trj]

My computer is a Dell Inspiron 560 that uses Windows 7. Other computer protection programs on computer: Malwarebytes Anti-Malware (Free Version), Comodo Firewall (Free Version), Windows Malicous Software Removal Tool, Microsoft Security Essentials, Windows Defender (Disabled).

Bunch of info on what I've tried:
When I found it, I first attempted to move it to the chest but there was an error that came up saying, "Error: The process cannot access the file because it's being used by another process (32)."

Screenshot of avast at this point: http://imageshack.us/photo/my-images/819/trojang.png/

Next I tried to apply the delete option and it said that it's "postponed until next reboot." So I restarted my computer. When I checked back at the scan log to see if the trojan was deleted, it still said "postponed until next reboot."

Since it still wasn't deleted, I tried to find the file myself and delete it manually. A message popped up saying "This action cannot be completed because this file is open in Windows Search."

Screenshot of message: http://imageshack.us/photo/my-images/163/filewontdelete.png/

After all that I tried scanning it with Malwarebytes Anti-Malware, Windows Defender, Windows Malicous Software Removal Tool, and Microsoft Security Essentials but they all failed to detect it. Then as a last resort, I tried sandboxing it in Comodo Firewall's sandbox but it didn't let me.

At the moment, the file still exists and I can't do anything about it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37562
  • Not a avast user
Re: Unremovable trojan found by avast! Need help please.
« Reply #1 on: September 22, 2012, 09:54:14 AM »
Quote
Microsoft Security Essentials
so you have avast and MSE installed?

never install multiple AV as this will slow down your machine, give mysterious windows errors, false positive detections, etc etc

so you need to uninstall one


Quote
When I found it, I first attempted to move it to the chest but there was an error that came up saying, "Error: The process cannot access the file because it's being used by another process (32)."
you need to turn off windows search
what OS do you have



« Last Edit: September 22, 2012, 10:02:33 AM by Pondus »

Needhelp200

  • Guest
Re: Unremovable trojan found by avast! Need help please.
« Reply #2 on: September 22, 2012, 11:26:41 AM »
Quote
Microsoft Security Essentials
so you have avast and MSE installed?

never install multiple AV as this will slow down your machine, give mysterious windows errors, false positive detections, etc etc

so you need to uninstall one


Quote
When I found it, I first attempted to move it to the chest but there was an error that came up saying, "Error: The process cannot access the file because it's being used by another process (32)."
you need to turn off windows search
what OS do you have

I only installed MSE after avast found the trojan because I got a little desperate trying to get rid of it. I now uninstalled MSE. How do I turn off windows search? I have a 64-bit Operating System with Service Pack 1.

EDIT: I turned off windows search and I wasn't able to find the file again so I turned windows search back on and it reappeared after a reboot. After scanning the same file again, avast reported that it isn't a threat anymore. Was it just a false positive or should I still be worried that my computer is compromised?
« Last Edit: September 22, 2012, 11:53:21 AM by Needhelp200 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unremovable trojan found by avast! Need help please.
« Reply #3 on: September 22, 2012, 12:50:10 PM »
Looking at the screenshots it is part of windows indexer, it was running whilst Avast was scanning.  And it appears to be a false positive.  However, for peace of mind I could take a quick look at your system

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
qmgr.dll
/md5stop
CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Post both logs

Needhelp200

  • Guest
Re: Unremovable trojan found by avast! Need help please.
« Reply #4 on: September 23, 2012, 01:56:59 AM »
EDIT: Didn't know I can attach files here lol. Here it is. Also ran a full avast and malwarebytes scan. It came up clean.
« Last Edit: September 23, 2012, 10:55:31 AM by Needhelp200 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unremovable trojan found by avast! Need help please.
« Reply #5 on: September 23, 2012, 01:39:34 PM »
That log looks clean as well, mark it as a flase positive  ;D

Run OTL and hit the cleanup button to remove it